Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 371

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Stocks making the biggest moves midday: Lennar, Capri, Vicor, Amgen & more
Texas Gov. Abbott orders data center permit halt weeks after issuing moratorium
Trump slams Iran and Cuba, defends AI growth and recounts record in UN speech
Trump snaps at CNN at United Nations: 'You should not be here covering me'
Snowpiercer: The First Blow Rewatch
How would you make the most of a micromanaging supervisor?
Iran reportedly says it can reopen Strait of Hormuz within 7 days if U.S. eases military pressure
Movie: De Gaulle: Resistance (2026)
Movie: Resident Evil: Extinction
Book: Murderland: Crime and Bloodlust in the Time of Serial Killers